Official Reverse Engineering Showcases & Guides
REA (rea-agents) has been verified across complex production applications: tracing Notion's Electron IPC clipboard bridge without source code, reconstructing DX-Ball's sound-pan calculation into verified C passing 3,205 test cases via Hopper, recovering 16-bit DOS bullet calculations in TH04 via Ghidra, and auditing Android APKs via headless JADX.
Notion: Trace the Electron Clipboard Bridge
Electron applications encapsulate complex preload bridges and IPC messages across separate operating system processes. In this official showcase, REA traces Notion's renderer clipboard API, follows it through preload and IPC into the main process, and reconstructs the rich clipboard data structure.
# Run static JavaScript/Electron inspection on Notion bundle
rea analyze-javascript-application /Applications/Notion.app/Contents/Resources/app.asar --json > notion-evidence.json
# Project a compact summary view (reducing 300MB+ Evidence to 10KB)
jq -c '{source: {kind: "inline", evidence: .}, view: {kind: "summary"}}' notion-evidence.json > notion-view.json
rea inspect-analysis-view notion-view.jsonWhen connected via MCP to Claude Code or Cursor, prompt your agent:
Find the renderer's clipboard API in Notion, follow it through preload scripts and IPC into the main process, and inspect how rich text formatting is serialized.DX-Ball: Reconstruct Sound-Pan Assembly into C
Using the Hopper Disassembler bridge (<code>--provider hopper</code>), REA follows a sound call in DX-Ball into its position-to-pan helper, analyzes compiled x86 machine instructions, and synthesizes standalone C source code that passes <strong>3,205 original-x86 test cases</strong> and reproduces all 63 compiled bytes.
# Inspect function dossier with call references
rea function ./dxball.exe SoundPanHelper --provider hopper --json
# Decompile x86 function into pseudocode
rea decompile ./dxball.exe 0x00401a20 --provider hopper --json
# Trace cross-references (xrefs)
rea xrefs ./dxball.exe 0x00401a20 --provider hopper --json// Verified C reconstruction passing 3,205 x86 test cases
int calculate_sound_pan(int ball_x_coord, int screen_width) {
if (screen_width <= 0) return 0;
int normalized = (ball_x_coord * 20000) / screen_width - 10000;
if (normalized < -10000) normalized = -10000;
if (normalized > 10000) normalized = 10000;
return normalized;
}TH04: Recover 16-Bit DOS Bullet-Ring Calculations
Through Ghidra's 16-bit DOS analysis module (<code>ghidra-dos</code>), REA parses segmented real-mode PC-98 machine code, reconstructs fixed-point trigonometric lookup tables, and compares the recovered algorithm against historical Borland C++ compiler output.
# Decompile segmented 16-bit real mode routine
rea decompile ./th04.exe 0x2000:0x0410 --provider ghidra --json
# Inspect raw disassembly sequence
rea instructions ./th04.exe 0x2000:0x0410 --provider ghidra --limit 50Android APK & JADX / ADB Extraction
For mobile applications, REA wraps headless JADX and Apktool to analyze Dalvik/ART classes, unpack resources, and monitor device logs via ADB without requiring a rooted device:
# Static APK class and manifest extraction
rea analyze ./mobile-app.apk --provider jadx --json
# Search decompiled classes for API endpoints
rea search ./mobile-app.apk 'api.v2' --provider jadx --json